Technical Tip: GRE + IPSec not supported for NP7 offloading
| Description | This article describes one scenario (GRE + IPSec) that is unsupported for NP7 offloading. |
| Scope | FortiGate. |
| Solution | NP7 offloading supports the GRE tunnel, including terminating on FortiGate or passing through FortiGate.NP7 offloading supports the IPSec VPN tunnel. However, if the traffic is GRE + IPSec VPN, whether it is GRE passing through the IPSec VPN or GRE over IPSec, it is not supported for NP7 offloading.
The workaround is to configure 2 VDOMs, with IPSec terminated in 1 VDOM and GRE terminated in another VDOM.
For example:
   Related documents: NP7 session fast path requirements |


